:::

詳目顯示

回上一頁
題名:風險評估模式應用於資訊安全管理之探討
書刊名:醒吾學報
作者:黃書猛張中權
作者(外文):Huang, Shu-mengChang, Chung-chen
出版日期:2006
卷期:31
頁次:頁147-169
主題關鍵詞:資訊安全管理系統風險分析脆弱性威脅BS7799ISO/IEC13355Risk assessmentVulnerabilityThreat
原始連結:連回原系統網址new window
相關次數:
  • 被引用次數被引用次數:期刊(2) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:2
  • 共同引用共同引用:0
  • 點閱點閱:21
隨著資訊快速普及化與電子商務興起,資訊的安全性要求也逐漸受到重視,如何執行資產價值評估、資產風險分析與風險處置,確保資訊資產(information asset)不會受側破壞、竊取與篡改,是目前資訊安全管理研究重要的議題。本文除就資訊安全主要相關標準作探討外,針對資訊安全之機密性、完整性及可用性三個構面,運用脆弱性、威脅模式(Asset/Vulnerability/Threat),建構風險分析的整體架構,最後舉一實例說明,羕能提供日後企業執行資訊安全風險評估之參考。
In the wake of the fast popularization of information and the rise of electronic commerce, information security is gradually gaining attention. How to perform the evaluation of the value of assets, how to perform the analysis of the risks associated with assets, and how to protect information assets fro sabotage, theft and tamper are currently the most important topics in the study of the management of information security. This research discusses the related standards of information security, and also addresses the aspects of confidentiality, integrated framework for risk analysis using vulnerability, threat of assets. Finally, the research results are illustrated by a case study. The results can be sued by business organizations as references or basis for information security planning and for management process improvements.
期刊論文
1.賴溪松(19980900)。資訊安全國家標準之應用與發展。資訊安全通訊,4(4),29-33。  延伸查詢new window
2.張真誠、婁德權(19970600)。資訊系統安全之對策。資訊與教育,59,41-47。  延伸查詢new window
3.樊國楨(19990600)。資訊及其相關技術之控管目的與應用簡介。資訊安全通訊,5(3),1-11。  延伸查詢new window
會議論文
1.Guan, B. C.、Lo, C. C.、Wang, P.、Hwang, J. S.(2003)。Evaluation of information security related risks of an organization- The application of multi-criteria decision-making method。IEEE 37th International Carnahan Conference on Security Technology (ICCST)。  new window
學位論文
1.劉永禮(2002)。以BS7799資訊安全管理規範建構組織資訊安全風險管理模式之研究(碩士論文)。元智大學。  延伸查詢new window
2.李慶民、莊謙亮(2001)。以BS 7799為基建構資訊安全評選模式之研究--以虛擬私有網路系統為例(碩士論文)。國防大學。  延伸查詢new window
3.黃慶堂(1999)。我國行政機關資訊安全管理之研究(碩士論文)。國立政治大學,台北。  延伸查詢new window
圖書
1.Stoneburner, Gary、Feringa, Alexis、Goguen, Alice(2002)。Risk Management Guide for Information Technology Systems。National Institute of Standards and Technology。  new window
2.(2002)。Information security management systems - Specification with guidance for use。  new window
3.溫鳳祺(2002)。風險管理--詞彙--標準使用指引。  延伸查詢new window
4.鄧家駒(2000)。風險管理。臺北:華泰文化事業公司。  延伸查詢new window
其他
1.British Standards Institution(2002)。Information Security Management- Part 2: Specification for Information Security Management Systems(BS7799-2)。(BS7799-2)。,London:British Standards Institution。  new window
2.ISO。Information technology - Guidelines for the management of IT Security(ISO/IEC TR 13335-3)。  new window
3.范淼(2002)。中科院「專案風險管理技術開發」課程。  延伸查詢new window
4.ISO/IEC(2000)。Information Technology--Code of Practice for Information Security Management(ISO/IEC 17799)。  new window
 
 
 
 
第一頁 上一頁 下一頁 最後一頁 top
QR Code
QRCODE