

題名:以BS 10012為基礎評估組織導入個人資訊管理制度之研究
作者:黃明達 引用關係張書鳴
主題關鍵詞:個人資料保護法個人資訊管理制度BS 10012ISO 27001PIMSPersonal information protection actPersonal information management system
原始連結:連回原系統網址new window
  • 被引用次數被引用次數:期刊(0) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:0
  • 共同引用共同引用:14
  • 點閱點閱:3
刑事警察局2009年165反詐騙專線統計指出,網路購物個人資料(以下簡稱個資)外洩詐騙事件排名第一,占全部詐騙數35%,顯示個資外洩情形嚴重。在個人資料保護法三讀通過後,組織一旦違法使用個資,將面臨高價求償金、刑責等問題,組織可能需開始著手規劃並實施針對個人資料的相關保護工作,降低個資法帶來的衝擊。本研究以問卷調查方式,分析各組織個人資料保護現況。發現商譽受損是最多組織不慎洩漏個資擔憂的衝擊,但中小企業與非營利事業對於須自行舉證組織並無故意或過失洩漏個資的困擾更甚於商譽受損。本研究以BS 10012為基礎之「規劃」、「實行與運作」、「監督與審查」、「改善」等四構面,評估組織的個人資訊管理制度(Personal Information Management System, PIMS)狀況,提供十種組織可優先加強構面之建議,如資訊服務業、金融業等組織在「規劃」構面、政府部門等在「實行與運作」構面、非營利組織等在「監督與審查」構面與電信業等在「改善」構面,建議強化個人資訊管理制度上的不足,使組織降低個資法將帶來的衝擊。
In 2009, Criminal Investigation Bureau 165 anti-fraud hotline statistics indicate that internet shopping frauds due to leakage of personal information were ranked first, accounting for 35% of frauds, indicating a serious problem of personal information leakage. After the Personal Information Protection Act third reading passed, if organization uses personal information illegally that will face high claims payments, criminal liability and other issues. To reduce impact from the Personal Information Protection Act, Organizations may need to begin to plan and implement relevant for the protection of personal information.This research is used the method of questionnaire survey, analysis of the status of personal information protection in organizations. Organization goodwill impairment is found in most organizations are concerned about the impact from accidental personal information leakage. But small and medium-sized enterprises and non-profit organizations are concerned about required to prove organizational without intention or negligence of personal information leakage problems more than organization goodwill impairment. Assess the organizational personal information management system base on "Plan", "Do", "Check", "Act", four phases of BS 10012, through analysis to provide 10 types of organizations priority advices on strengthen phase, such as "information services industry" and "financial services industry" in the "plan" phase, "government departments" in the "Do" phase, "non-profit organizations" in the "Check" phase, and "telecommunications industry" in the "Act" phase. Strengthening Lack of personal information management system will enable to reduce impact from the Personal Information Protection Act.
1.李振瑋、江耀國(20100600)。英國資料保護法中資料所有人權利之研究--兼論我國個資法之相關規範及案例。中原財經法學,24,29-85。new window  延伸查詢new window
2.蒲樹盛(20100700)。創新科技環境下的資訊管理重點--雲端資訊安全、個資隱私保護、營運持續服務。品質月刊,46(7),22-25。  延伸查詢new window
3.Lusoli, W.、Compañó, R.(2010)。From security versus privacy to identity: an emerging concept for policy design。Info,12,80-94。  new window
4.Jones, W.(2007)。Personal information management。Annual Review of Information Science and Technology,41(1),453-504。  new window
5.Raman, J.(2008)。European court of human Rights: failure to take effective information security measures to protect sensitive personal data violates right to privacy。Computer Law & Security Report,24(6),562-564。  new window
6.翁清坤(20100700)。論個人資料保護標準之全球化。東吳法律學報,22(1),1-60。new window  延伸查詢new window
1.Korba, L.(2002)。Privacy in distributed electronic commerce。The 35th Hawaii International Conference on System Science,306。  new window
1.曾淑惠(2002)。以BS7799為基礎評估銀行業的資訊安全環境(碩士論文)。淡江大學。  延伸查詢new window
1.BSI Group(2009)。Data protection: specification for a personal information management system。London:BSI。  new window
2.APEC(2004)。APEC Privacy Framework。  new window
3.BSI Group(2009)。Data dilemma: one in five businesses admit breaching the data protection act。  new window
4.ICO(2007)。The principles of the data protection act in detail。  new window
5.OECD(1980)。OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data。  new window
1.張毓仁(2010)。新版個資法之影響與商機,http://mic.iii.org.tw/aisp/reports/reportdetail2.asp?sesd=685865671&docid=CDOC20100601006&doctype=RC&cate=&smode=1&countrypno。  new window
2.郭戎晉(2009)。國際個人資料保護制度鳥瞰,http://gcis.nat.gov.tw/ec/knowledge/notes/doc_download.asp?DocID=1137。  延伸查詢new window
3.中華民國國家資訊基本建設產業發展協進會NII(2007)。2007台灣網路安全信心調查,http://als.org.tw/article/new_paper_sg.asp?id=168。  延伸查詢new window
4.Alston & Bird(2006)。Asia-Pacific E-Commerce & Privacy Forum Policy Advisory: Japan's Personal Information Protection Act and its Key Guidelines to be Revised,http://www.alston.com/Files/Publication/eaa94801-4e73-438c-aa8a-7e141ad98122/Presentation/PublicationAttachment/9015d6ba-fcab-4c02-87c5-0ab12dc449c4/PIPA%20Guidelines.pdf。  new window
第一頁 上一頁 下一頁 最後一頁 top
QR Code