台灣企業實施資訊安全管理系統關鍵成功因素調查

台灣企業實施資訊安全管理系統關鍵成功因素調查
*許瑋麟a 郭仁宗b 何玉菁c
摘要

 

由於資訊科技及網際網路的蓬勃發展,資訊安全管理儼然是目前企業最重要的研究議題之一,特別是目前已有許多企業已導入資訊安全標準(例如BS7799 or ISO27001)並建置資訊安全管理系統(information security management systems, ISMS),以達成資訊安全(資安)管理目標。本研究以量化問卷調查台灣企業實施資訊安全管理系統關鍵成功因素,研究發現企業普遍認為導入ISMS 最重要的六個關鍵成功因素(Key Successful Factor, CSF)為:「高階主管支持」、「資安政策宣導」、「資安顧問互信程度」、「員工認同及參與度」、「資安管理制度的合理性」以及「資安素養」。研究並發現已導入ISMS 的企業和未導入ISMS 的企業在「明確的ISMS資安政策」、「資安風險管理」、「資安顧問互信程度」、「資安教育訓練」、「同業競爭者壓力」等五項成功因素上有顯著的認知差異。本研究的發現可以提供實務上正規劃備導入ISMS 的企業參考,以期能順利成功的導入ISMS 並進一步為企業提升資訊安全管理的效益與成效。
 

關鍵語:資訊安全管理、資訊安全管理系統、關鍵成功因素。

 

----------------------------

 

The survey of critical successful factors of information security management systems in Taiwan
 

*Wei-Lin Hsua Ren-Chung Kuob  Yu-Ching Hoc
 

Abstract
 

  As information technology and Internet are rapid developed and widely used, information security management becomes one of the most important research issues to business, especially now there are many companies implement information security management systems (ISMS), e.g. BS7799 or ISO27001, to maintain their information assets safety with confidentiality、integrity、availability. The aim of this research is to investigate critical successful factors CSFs) of the information security management systems introduced or implemented in enterprises in Taiwan. The finding results show that the top 6 CSFs are: top management support; ISMS policy introduction; mutual trust between ISMS consultant; employee recognition and participation; reasonable ISMS disciplines; and, ISMS professional concepts. This research also reveals that there are significant concept differences on five CSFs (clear ISMS policy; ISMS risk management; mutual trust between ISMS consultant; ISMS education and training; and, the pressure from industry competitors) between those enterprises ISMS implemented and those not implemented. These findings could provide valuable CSFs to those enterprises which are planning to introduce and implement ISMS. Taking these CSFs into account, it is expected that enterprises will successfully implement ISMS and gain their benefits and advantages.
 

Keywords:Information Security Management、Information Security Management Systems Critical
Successful Factors.