[1]陳培德、賴溪松,2002,Communications of the CCISA。
[2]楊仕全,「階層分析法在企業選用即時傳訊軟體安全管理策略風險評估模式之研究」,華梵大學資訊管理學系研究所碩士論文,民國九十五年六月。[3]林勤經,「內部網路遭駭客攻擊方式與防護之研究」,臺灣大學資訊管理學系研究所碩士論文,民國九十三年六月。[4]吳琮璠、謝清佳,2000,資訊管理理論與實務,台北,智勝文化事業有限公司,第四版
[5]王玉婷,2004,資安威脅動態探索系統之分析應用與實作,靜宜大學資訊管理學系研究所。[6]黃明達、朱家璁,「駭客入侵方法與對策之研究」,資訊管理展望,第三卷第二期,第35-49頁,民國九十年。
[7]王旭正、高大宇,「視窗木馬程式的安全鑑別與防制策略研究」, National Infrmation Security Coference,民國九十年。
[8]李宜揚,「駭客攻擊模式探討與木馬程式進階技術」,資策會,網路及通訊實驗室。
[9]郭志賢,2003,以BS7799為基礎評估大學資訊中心之資訊安全管理-以淡江大學為例,淡江大學資訊管理學系。[10]蘇俊偉,2003,網路安全威脅分析與防制策略,東海大學資訊工程與科學系碩士在職專班
[11]張哲郎,2004,中小企業資訊安全架構-以Microsoft Windows系統平台為例,國立清華大學資訊系統與應用研究所。[12]沈榮華,2002,網路犯罪相關問題之研究,國防管理學院法律研究所。[13]沈文吉,2000,網路安全監控與攻擊行為之分析與實作,國立臺灣大學資訊管理研究所。[14]吳文進,2004,利用排除的觀念改善入侵偵測特徵比對效能之研究,華梵大學資訊管理學系碩士班。[15]林慶南,2002,以網站日誌檔探勘加強網頁伺服器的安全性,中原大學電子工程研究所碩士論文。[16]蒲樹盛,2004,電腦稽核期刊第10期p17-25。
[17]高進光,2004,電腦稽核期刊第10期p35-45。
[18]李欣陽,2004,電腦稽核期刊第11期p105-111 Communications of the CCISA。
[19]黃士銘、莊盛祺,2005,ACL資料分析與電腦稽核教戰手冊,全華。
[20]黃明達、徐正,「組織導入BS7799 後之資訊安全管理成效研究」,淡江大學,ICIM2006,p.1651-1658。
[21]陳瑞祥,「內部稽核如何執行資通安全檢查」,KPMG,2002。
[22]洪國興、季延平、趙榮耀,組織制定資訊安全政策對資訊安全之研究,資訊管理研究所,2003年,第3期。
[23]劉智敏,「運用BS7799 建構資訊安全風險管理指標」,國立台北大學企業管理學系碩士論文,民國九十三年。
[24]資訊安全風險管理,資通安全專輯之五,行政院國家科學委員會科學技術中心編印,第四~五章,2002
[25]葉明哲、廖耕億,「資訊系統風險分析方法之現況與展望」,第三屆產業資訊管理暨新興科技學術研討會,2002年。
[26]曾國雄、蕭再安、鄧振源,多評準決策方法之分析比較,科學發展月刊,1989年,第16卷,第7期,頁1008-1017。[27]高進光,2004,電腦稽核期刊第10期p35-45。
[28]高愛琴,2005,以平衡計分卡為基礎建構資訊安全管理關鍵績效指標,國立中正大學資訊管理學系碩士論文。[29]謝玲芬(1989)。多目標(多準則)評估技術之探討及其在組織績效評估之應用。國立清華大學工業工程研究所碩士論文。[30]鄧振源、曾國雄,層級分析法(AHP)的內涵特性與應用(上),中國統計學報,1989年,第27卷,第6 期,頁5-22。[31]鄧振源、曾國雄,層級分析法(AHP)的內涵特性與應用(下),中國統計學報,1989年,第27 卷,第7 期,頁1-20。[32]羅應浮、陳貞元、 林青衿、 陳雅汶、 張琇妏、 賴虹伶,發展經營網路商店之決策支援系統─運用模糊AHP法,第十一屆資訊管理暨實務研討會,2005。
[33]Ellison RJ,Fisher DA,Linger RC, Lipson HF, Longstaff TA,Mead NR.Survivability:protecting your critical systems.IEEE Internet Comput Novembere Decemver 1999.
[34]Baird, I.S and Thomas,H, Toward a contingency model of strategic risk taking. Academy of Management Review, Vol. 10, 1985, pp.230-243。
[35]Ken,S.2002 “Web Application Security,Information SystemsControl Journal,Vol.6,pp.44-46。
[36]Pipkin,2000,Donald L.Pipkin,Information security,Hewlett-Packard Professional Books,2000
[37]Porter D.Insider fraud:spotting all the wolf in sheep,clothing Computer Fraud and Security 2003;2003(4):12e5
[38]Schultz,E.Eugene and Shumway,Russe11,Incident Response:A Strategic guide to Handling System and Network Security Breaches,Que,2002.
[39]Post,G.and Kagan,A.,”Management Tradeoffs in Anti-Virus Strategies,”Information and Management,2003,37,13-24
[40]Loch,K.D.,Carr H.H.,and Warkentin M.E.,Threats to Information Systems:Today Rea;out Yesterday Understanding,”MIS Quarterly,June 1992,173-186.
[41]Carter,DL.,Katz A.J.,”Computer Crime and Security:The Perceptions and Experiences of Corporate Security Directors,”Security Journal,1996,7,101-108
[42]Hoffer Jeffrey A, Straub Detmar W. The 9 to 5 undeground:are you policing computer crimes Sloan Management Revies Summer 1989;30(4):35.
[43]Adam,F.,and Haslam,J.A.,”The Irish Experience with Disaster Recovery Planning:High Level of Awareness May Not Sufficient,”in G.Dhillon Eds. Information Security Managemet:Global Challenges in the New Millennium,Hershey PA:Idea Group Publishing,2001,85-100
[44]Hallington,s.,The Effect of Codes of Ethics and Personal Denial of Responsibility on Computer Abuse Judgments and Intension,”MIS Quarterly,September 1996,257-278
[45]Caminada,M.;”Internet security incidents,a survey within Dutch organizations”;Computers&security,17(1998)417-433
[46]Austin,R.D.,Darby C.A and Christopher A.R.2003. The Myth of Secure Computing”Harvard business Review 81
[47]Chris Pounder “The Revised Version of BS7799 – So What’s New” Computers & Security,18(199)307-311。
[48]BSI(1999),”Information security management- Part1:Code or practice for information security management”,BS7799-1:2000,BSI(British Standards Institution)。
[49]BSI(1999),”Information security management- Part2:Specification for information security management systems”,BS7799-2:1999,BSI(British Standards Institution)