:::

詳目顯示

回上一頁
題名:Exploring ISMS Implementations from the Organizational Learning Perspective:A multi-Case Study in Taiwan
書刊名:電腦稽核
作者:廖耕億 引用關係陳昱仁 引用關係蕭光妤
作者(外文):Liao, Gen-yihChen, Yu-jenHsiao, Kuang-yu
出版日期:2014
卷期:30
頁次:頁90-103
主題關鍵詞:資訊安全管理制度組織學習安全意識個案研究Information security management systemISMSOrganizational learningSecurity awarenessCase study
原始連結:連回原系統網址new window
相關次數:
  • 被引用次數被引用次數:期刊(0) 博士論文(0) 專書(0) 專書論文(0)
  • 排除自我引用排除自我引用:0
  • 共同引用共同引用:0
  • 點閱點閱:35
資訊安全管理制度的建置,是一個牽涉安全、技術、法律、組織、管理等多層面複雜知識的過程。為了瞭解組織於其過程中可能遭遇的阻礙,並且從組織學習觀點找出可能影響導入過程的影響因子,本研究執行質性研究方法,深入探索四個公務單位的資訊安全管理制度導入過程。研究結果發現,組織氣氛、個人與團隊實務、個人與團隊發展、報酬等四因素,與資安管理制度知識的缺乏現象有關。此外,本研究亦發現,資安意識與資安管理制度的文件化、資安管理制度知識與重要性評價、報酬/認同與流程標準化程度四組變數之間,也可能存在相關。本研究從組織學習觀點提出具體建議,希冀輔助相關組織於導入時增強知識體質,提升導入成功的可能性。
Implementing an ISMS is a challenging task, as most workers cannot well deal with information security issues. To realize what obstacles organizations may encounter and to find out whether the organizational learning factors affect the implementation process, this investigation conducted qualitative methodology and interviewed four public organizations in Taiwan. The research findings offer a research model of reduced complexity, which can be validated and tested quantitatively. The results indicate that four factors may lead to insufficient ISMS-related knowledge. Besides, we also find potential relationships may exist between security awareness and ISMS documentation, between ISMS-related knowledge and valuation towards the importance of security management, and between rewards/recognition and standardization. A few conceptual explanations are offered to benefit those organizations which remain in the early phase of ISMS implementation.
期刊論文
1.Nevis, E. C.、DiBella, A. J.、Gould, J. M.(1995)。Understanding organizations as learning systems。Sloan Management Review,36(2),73-85。  new window
2.Friedlander, F.、Brown, L. D.(1974)。Organization Development。Annual Review of Psychology,25(1),313-341。  new window
3.Redding, John(1997)。Hardwiring the Learning Organization。Training & Development,51(8),61-67。  new window
4.Rockart, J. F.、Scott Morton, M. S.(198401)。Implications of Changes in Information Technology for Corporate Strategy。Interface,14(1),84-95。  new window
5.Jan, Z.(2005)。Discovering the Value Behind the BS 7799 Certificate: Experience Sharing After One-year Certification。Information Security,19,28-33。  new window
6.Wick, C. W.、Leon, L. S.(1995)。From Ideas to Action: Creating a Learning Organization。Human Resource Management,34(2),299-311。  new window
7.Bennett, Joan Kremer、O'Brien, Michael J.(1994)。The Building Blocks of the learning Organization。Training,31(6),41-49。  new window
8.Ajzen, Icek(1991)。The theory of planned behavior。Organizational Behavior and Human Decision Processes,50(2),179-211。  new window
會議論文
1.Bennett, J. K.、O'Brine, M. J.(1994)。Measuring and Building a Learning Organization: A Systems Approach。Eighth IEEE-USA Careers Conference。  new window
圖書
1.Zalabak-Shockley, P. S.(2005)。Fundamentals of organizational communication: Knowledge, sensitivity, skills, values。Boston, MA:Allyn and Bacon。  new window
2.Marquardt, Michael J.、Reynolds, Angus(1994)。The global learning organization。Chicago。  new window
3.Marquardt, Michael J.(1996)。Building the Learning Organization: A System Approach to Quantum Improvement and Global Success。McGraw-Hill Companies, Inc.。  new window
4.Chou, Y.(2000)。Designing an Assessment Scale for Learning Organizations。Tao-Yuan:National Central University。  new window
5.Cummings, T. G.、Worley, C. G.(2004)。Organization Development and Change。South-Western College。  new window
6.Peltier, T. R.(2002)。Information Security Policies, Procedures, and Standards。New York:Auerbach。  new window
7.Miles, Mathew B.、Huberman, A. Michael(1994)。Qualitative data analysis: A sourcebook of new methods。Sage Publications。  new window
8.Robbins, Stephen P.(2001)。Organizational behavior。Prentice-Hall, Inc.。  new window
9.Peltier, T. R.(2001)。Information Security Risk Analysis。New York, NY:Auerbach。  new window
其他
1.ISMS International User Group(2012)。International register of ISMS certificates,http://www.iso27001certificates.com/Register%20Search.htm, 2012/01/01。  new window
2.ISO(2005)。Information Technology--Security Techniques--Information Security Management Systems--Requirements(ISO/IEC 27001)。,Geneva:ISO。  new window
3.British Standards Institution(2002)。Information Security Management Systems--Specification with guidance for use(BS7799-2)。,London。  new window
圖書論文
1.Leavitt, H. J.(1965)。Applying organizational change in industry: Structural, technological and humanistic approaches。Handbook of Organizations。Skokie, IL。  new window
 
 
 
 
第一頁 上一頁 下一頁 最後一頁 top
QR Code
QRCODE