:::

詳目顯示

回上一頁
題名:企業導入BS7799資訊安全管理系統之關鍵成功因素--以石化產業為例
書刊名:資訊管理學報
作者:黃士銘 引用關係張碩毅 引用關係蘇耿弘
作者(外文):Huang, Shi-mingChang, She-iSu, Keng-hung
出版日期:2006
卷期:13:2
頁次:頁171-192
主題關鍵詞:資訊安全管理關鍵因素石化產業BS7799ISO17799Information security managementCritical success factorsPetrochemical industry
原始連結:連回原系統網址new window
相關次數:
  • 被引用次數被引用次數:期刊(4) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:4
  • 共同引用共同引用:0
  • 點閱點閱:27
隨著電子交易的發展,資訊安全逐漸受到企業重視。「BS 7799」是由英國國家標 準協會(BSI)於1995年所制定;企業只要做到BS7799的要求,並通過獨立稽核機構評鑑,便可獲頒BS7799資訊安全認證。因此,可向其客戶與合作夥伴宣告,該企業網路內與他們相關的資料都受到適當的保護,而且該企業整體的安全度也值得信任。國外許多石化公司紛紛建立供應鏈體系及電子市集,以期降低交易成本、掌握市場趨勢及交換市場訊息。而國內由經濟部工業局推動「石化產業電子化標準推動計劃」,積極輔導業者成立電子化產銷體系,以因應國際化之電子交易趨勢。另外石化業者為即時掌握生產狀況及監控工廠運作情形,利用網路、控制介面及數據擷取等技術將程控資訊與管理資訊系統整合,為管理上帶來極大的便利。但相對地因資訊安全問題所造成的風險會更加嚴重,由於石化原料及產品多屬易燃物,其所造成的影響不僅是資訊及經濟的損失,嚴重時可能造成公共安全問題,使得石化產業的資訊安全更應受到重視。本研究以BS7799為基礎,針對國內石化產業的資訊安全議題及現況進行調查,以暸解該產業資訊安全狀況及其差異。並利用區別分析找出影響石化產業導入資訊安全管理機制的關鍵成功因素。研究發現其關鍵成功因素分別為安全防護、資訊安全技能、供應商、法令規章、競爭壓力、商業夥伴影響、安全事件處理、員工參與、電腦化程度、高階主管支持、組織規模及安全風險程度等因素。
Due to the rapid development of electronic commerce, maintaining information security in order to protect information assets is a key concern for every enterprise today. The BS7799 administrated by the British Standards Institute (BSI) since 1995, is a comprehensive system for implementing effective Internet security, by far, it is the most appropriate approach to best practices for information security management. By gaining the BS7799 certification, companies may assure customers and partners that their data, which being kept on the enterprise networks, will be secure and that the overall security of the enterprise is trustworthy. In the case of Petrochemical manufacturing industry, in Taiwan, many companies try to minimize the cost and achieve their gross profit margin by implementing e-commerce and applying vendors' supply chain management technology. The purpose of this study is to explore the critical success factors for the implementation of information security management system in the Petrochemical Industry. The results reveal that factors such as information security protection, information security skill, supplier, industrial regulations, competitive pressure, the interdependence among business partners, occupational health and safety practice, degree of computerization, top management support, scale of organization and tolerant of risk are crucial to the success for implementing the business electronically.
期刊論文
1.Premkumar, G.、Ramamurthy, K.、Nilakanta, S.(1994)。Implementation of Electronic Data Interchange: An Innovation Diffusion Perspective。Journal of Management Information Systems,11(2),157-186。  new window
2.Eloff, M. M.、Von Solms, S. H.(2000)。Information Security Management: An Approach to Combine Process Certification and Product Evaluation。Computers and Security,19(8),698-709。  new window
3.張振接(2001)。打造堅不可摧的國產Linux OS-為Power by Taiwan的「資訊安全產業」催生。軟體產業通訊,43,13-21。  延伸查詢new window
4.蒲樹盛(2004)。臺灣金融業應用BS7799資訊安全管理系統(ISMS)分析。電腦稽核,10,17-25。new window  延伸查詢new window
5.Caminada, M.(1998)。Internet Security Incidents, a Survey within Dutch Organizations。Computers & Security,17(1),417-433。  new window
6.Chau, Jacqui(2005)。Skimming the Technical and Legal Aspects of BS7799 Can Give a False Sense of Security。Computer Fraud & Security,9,8-10。  new window
7.Cohen, F.(1998)。A Cause and Effect Model of Attacks on Information Systems。Computers & Security,17(1),221-226。  new window
8.Kankanhalli, A.、Teo, H. H.、Bernard, B. C. Y.、Wei, K. K.(2003)。An Integrative Study of Information Systems Security Effectiveness。Informational Journal of Information Management,13,139-154。  new window
9.Powell, D.(1993)。To Outsourcing or Not to Outsourcing?。Networking Management,56-61。  new window
10.Solms, Basie Von(2001)。Information Security Multidimensional Discipline。Computers & Security,20(1),504-508。  new window
11.Solms, Basie Von、Solms, Rossouw Von(2001)。Incremental Information Security Certification。Computers & Security,20(1),308-310。  new window
12.Trcek, D.(2003)。An Integral Framework for Information Security Management。Computers & Security,22(4),337-360。  new window
會議論文
1.Huang, H. Y.、Huang, H. G.、Yen, D. C.(2000)。A Study on Internet Security Factors of Different Financial Institutions in Taiwan。0。  new window
學位論文
1.吳俊德(2002)。ISO 17799資訊安全管理關鍵重點之探討,0。  延伸查詢new window
2.曾淑惠(2002)。以BS 7799為基礎評估銀行業的資訊安全環境,0。  延伸查詢new window
圖書
1.Hair, J. F.、Anderson, R. E.、Tatham, R. L.、Black, W. C.(1995)。Multivariate data analysis with readings。Upper Saddler River, NJ:Prentice-Hall。  new window
2.(2002)。產業電子化白皮書。產業電子化白皮書。臺北。  延伸查詢new window
3.臺灣區石化公會(2001)。臺灣區石化公會九十年石化工業概況。臺灣區石化公會九十年石化工業概況。臺北市。  延伸查詢new window
4.British Standards Institution(2000)。Information Security Management- Part 1: Code of Practice for Information Security Management。Information Security Management- Part 1: Code of Practice for Information Security Management。0。  new window
5.British Standards Institution(2002)。Information Security Management- Part 2: Specification for Information Security Management Systems。Information Security Management- Part 2: Specification for Information Security Management Systems。0。  new window
6.Root, Steven J.(1998)。Beyond COSO: Internal Control to Enhance Corporate Governance。Beyond COSO: Internal Control to Enhance Corporate Governance。New York, NY。  new window
其他
1.沈倩如(2001)。美國電子商務簡易市調,0。  延伸查詢new window
2.游輝祥(2001)。工廠資訊管理系統,0。  延伸查詢new window
3.經濟部標準檢驗局(2002)。資訊安全管理系統(ISMS)-CNS 17800標準,0。  延伸查詢new window
4.葉瑞萍(2001)。製程資訊整合實廠建置經驗談,0。  延伸查詢new window
5.Symantec(2000)。Symantec Enterprise Solutions,0。  new window
 
 
 
 
第一頁 上一頁 下一頁 最後一頁 top
QR Code
QRCODE