Security Auditing Management for Cloud Campus Information Systems Using ISO 27001-A Case Study on School Affairs Information Systems of Some Junior High School in Hsinchu City

碩士 === 大葉大學 === 資訊管理學系碩士班 === 105 === Due to ever-changing evolutions of information technology, lots of data need to rely on cloud computing. Both of the institutions of government and enterprises have to require information systems to maintain the organizational operations through cloud computing...

Full description

Bibliographic Details
Main Authors: HUANG,CHING-WEN, 黃靖雯
Other Authors: TSAUR WOEI-JIUNN
Format: Others
Language:zh-TW
Published: 2017
Online Access:http://ndltd.ncl.edu.tw/handle/4sj2ef
Description
Summary:碩士 === 大葉大學 === 資訊管理學系碩士班 === 105 === Due to ever-changing evolutions of information technology, lots of data need to rely on cloud computing. Both of the institutions of government and enterprises have to require information systems to maintain the organizational operations through cloud computing. And there is no exception to campus information systems. For example, the scores and personal data of students must be uploaded to the campus systems with serious protection. This is the reason why the security auditing management for cloud campus information systems is very important. This study is based on ISO 27001 information security management standard and Plan-Do-Check-Act Model to design interview questions and adopt the method of case study. Through the in-depth interview, we have inspected the network crisis management of cloud campus information systems in some junior high school in Hsinchu City. Based on the findings in this research, they have following contributions. One, few human resources are for securing the cloud campus information system. Second, employees have poor knowledges and lacking in responsibility. Third, few resources to support security are from the government. Finally, it must emphasis the iterations on the method of Plan-Do-Check-Act for the security of cloud campus information systems. Therefore, this study proposes five suggestions in the following. (1) More educated employees to implement the security of cloud campus information systems. (2) To setup the awards to encourage the study on securing information system. (3) Different responsibility to consider the different users’ behaviors. (4) Request more resources from the government to improve the status. (5) Through the iterations on Plan-Do-Check-Act model to implement the security of cloud campus information systems. We hope the research results are also useful for other junior high schools in the future.