A Case Study of Information Security Management System
碩士 === 元智大學 === 資訊管理學系 === 103 === In October 2013, the ISO/IEC 27001:2013 was published by the International Organization for Standardization. All certificates to ISO/IEC 27001:2005 have to be renewed prior to September 2015, otherwise they were expired automatically. Conducting documentary analysi...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Online Access: | http://ndltd.ncl.edu.tw/handle/45446173468095668855 |
id |
ndltd-TW-103YZU05396043 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-103YZU053960432016-09-25T04:04:59Z http://ndltd.ncl.edu.tw/handle/45446173468095668855 A Case Study of Information Security Management System 資訊安全防護與管理之個案研究 Ching-Hui Kuo 郭晴慧 碩士 元智大學 資訊管理學系 103 In October 2013, the ISO/IEC 27001:2013 was published by the International Organization for Standardization. All certificates to ISO/IEC 27001:2005 have to be renewed prior to September 2015, otherwise they were expired automatically. Conducting documentary analysis and case study methods, this study attempted to explore how one government agency transited to the new version with limited budget and time, and analyzed the actual implement procedures. The staffs in the government agency and information security consultants participated in the in-depth interview. The findings of the study show that the scope of the original information security management system did not include core activities. Based on the ISO/IEC 27001:2013, the agency reviewed the current system documents, added revised standard procedures, carried out the risk assessments, and conducted internal audit checks and training sessions. In order to draw continuous attention, and obtain support and assistance from the executives, the implement progress was reported in the executive meetings. In addition, bulletin announcements and training sessions were organized to earn the recognition of colleagues. The goal of the information security was achieved in the management dimension and in the technical dimension. Security and convenience always stand on the both sides of the scale, and it is planners’ importance task to keep them balance. To plan and promote the information security management, manpower, resources, time and budgets are all crucial. Yi-Chuan Lu 盧以詮 學位論文 ; thesis 44 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 元智大學 === 資訊管理學系 === 103 === In October 2013, the ISO/IEC 27001:2013 was published by the International Organization for Standardization. All certificates to ISO/IEC 27001:2005 have to be renewed prior to September 2015, otherwise they were expired automatically. Conducting documentary analysis and case study methods, this study attempted to explore how one government agency transited to the new version with limited budget and time, and analyzed the actual implement procedures. The staffs in the government agency and information security consultants participated in the in-depth interview. The findings of the study show that the scope of the original information security management system did not include core activities. Based on the ISO/IEC 27001:2013, the agency reviewed the current system documents, added revised standard procedures, carried out the risk assessments, and conducted internal audit checks and training sessions. In order to draw continuous attention, and obtain support and assistance from the executives, the implement progress was reported in the executive meetings. In addition, bulletin announcements and training sessions were organized to earn the recognition of colleagues. The goal of the information security was achieved in the management dimension and in the technical dimension. Security and convenience always stand on the both sides of the scale, and it is planners’ importance task to keep them balance. To plan and promote the information security management, manpower, resources, time and budgets are all crucial.
|
author2 |
Yi-Chuan Lu |
author_facet |
Yi-Chuan Lu Ching-Hui Kuo 郭晴慧 |
author |
Ching-Hui Kuo 郭晴慧 |
spellingShingle |
Ching-Hui Kuo 郭晴慧 A Case Study of Information Security Management System |
author_sort |
Ching-Hui Kuo |
title |
A Case Study of Information Security Management System |
title_short |
A Case Study of Information Security Management System |
title_full |
A Case Study of Information Security Management System |
title_fullStr |
A Case Study of Information Security Management System |
title_full_unstemmed |
A Case Study of Information Security Management System |
title_sort |
case study of information security management system |
url |
http://ndltd.ncl.edu.tw/handle/45446173468095668855 |
work_keys_str_mv |
AT chinghuikuo acasestudyofinformationsecuritymanagementsystem AT guōqínghuì acasestudyofinformationsecuritymanagementsystem AT chinghuikuo zīxùnānquánfánghùyǔguǎnlǐzhīgèànyánjiū AT guōqínghuì zīxùnānquánfánghùyǔguǎnlǐzhīgèànyánjiū AT chinghuikuo casestudyofinformationsecuritymanagementsystem AT guōqínghuì casestudyofinformationsecuritymanagementsystem |
_version_ |
1718385612529074176 |