跳到主要內容

臺灣博碩士論文加值系統

(216.73.216.151) 您好!臺灣時間:2026/09/03 17:29
字體大小: 字級放大   字級縮小   預設字形  
回查詢結果 :::

詳目顯示

: 
twitterline
研究生:陳慶儒
研究生(外文):Chen,Ching-Ju
論文名稱:影響資訊安全管理策略效益因素研究-以C金控公司為例
論文名稱(外文):Effect of Information Security Management Strategy Effectiveness Factors-an empirical study of financial holding company C
指導教授:李慶長李慶長引用關係
指導教授(外文):Lee,Ching-Chang
學位類別:碩士
校院名稱:國立臺北商業大學
系所名稱:商學研究所
學門:商業及管理學門
學類:一般商業學類
論文種類:學術論文
論文出版年:2016
畢業學年度:104
語文別:中文
論文頁數:63
中文關鍵詞:資訊安全資訊安全管理TOETAM
外文關鍵詞:Information SecurityInformation Security ManagementTOETAM
相關次數:
  • 被引用被引用:2
  • 點閱點閱:307
  • 評分評分:
  • 下載下載:20
  • 收藏至我的研究室書目清單書目收藏:1
回顧過往資訊安全相關議題研究,大多著重在內、外部環境因素與資訊安全策略實施關聯或資訊安全效益合理投資之研究,而較少對影響資訊安全管理策略效益進行分析探討,尤其是現今內、外部環境因素不斷地改變,資訊安全保護工作備受挑戰。企業組織除了適時調整資訊安全管理策略外,更應瞭解在資訊安全管理策略下所獲得的資訊安全效益,是否符合企業組織整體經營風險管理目標。因此,本研究針對內、外部環境因素影響企業組織的資訊安全管理策略,及其管理策略下所獲取的資訊安全效益進行分析探討,經由本研究實證探討後,企業組織可從科技-組織-環境三方面的內、外部環境因素,客觀評估並制定合宜的資訊安全策略,並可藉由企業組織內部人員對資訊安全策略易學易用的認知共識,或透過公允的第三方認證持續維持企業組織制定的資訊安全標準,即可獲取客戶滿意回饋並提高企業組織良好聲譽的資訊安全效益。
Recalling the past, information security research related issues, including most emphatically, research associate or information security benefit justifies the investment of external environmental factors and information security policy enforcement, and less on the impact of information security management strategies benefit analysis to explore. Especially within today, internal and external environmental factors are constantly changing, information security protection work is highly challenging. In addition to timely adjust organizational information security management strategy, but also should be aware of information security benefit in information security management strategy obtained, whether the organization's overall business risk management objectives. Therefore, in this study will, internal and external environmental factors that affect organizational information security management strategy, and information security benefits acquired under management strategy were analyzed and discussed. Organizations from three aspects of the internal and external environmental factors, Technology - Organization - Environment, objectively assess and develop appropriate information security policies. And by personnel within the organization of information security policies easy to use and cognitive consensus, or continue to maintain corporate information security standards through third party certification organizations, to get feedback and improve customer satisfaction, organizational reputation information security benefits.
摘要........i
ABSTRACT....ii
誌謝........iii
表目錄......v
圖目錄......vi
第一章 緒論...........................1
第一節 研究背景........................1
第二節 研究目的........................3
第三節 研究流程........................4
第二章 文獻探討........................5
第一節 資訊安全策略.....................5
第二節 科技-組織-環境(TOE)架構...........9
第三節 人員認知........................10
第四節 資訊安全認證.....................12
第五節 資訊安全效益.....................13
第三章 研究方法........................15
第一節 研究架構........................15
第二節 研究對象........................16
第三節 研究假說........................16
第四節 變數定義與衡量...................22
第五節 資料分析與統計方法................26
第六節 問卷前測結果分析..................28
第四章 資料分析與實證研究................32
第一節 樣本結構分析.....................32
第二節 共同方法變異分析..................36
第三節 信度分析.........................36
第四節 效度分析.........................37
第五節 假說檢定.........................39
第五章 結論與建議.......................48
第一節 研究結論.........................48
第二節 管理與實務意涵....................52
第三節 研究限制及後續研究建議.............54
參考文獻................................55
附錄...................................59

中文文獻:
何雍慶 & 蔡青姿 (2009)。運用 PLS 方法探討價值創新導入新產品開發之調節角色。中華管理評論國際學報。12(2)。
洪肇蔚 (2004)。資訊安全建置最適化投資策略之研究。國立成功大學碩士論文。
黃芳銘 (2002)。結構方程模式-理論與應用。台北:五南書局。
黃俊英 & 林震岩 (1994)。SAS 精析與實例。台北:華泰書局。
iThome (2014)。IT大事回顧。2015年1月5日。
取自:http://www.ithome.com.tw/voice/93355。
微軟,Partner Network (2011)。資訊安全概論。
取自:https://partner.microsoft.com/taiwan/40068847。


英文文獻:
Adams, D. A., Nelson, R. R., & Todd, P. A. (1992). Perceived usefulness, ease of use, and usage of information technology: A replication. MIS quarterly, 16(2), 227-247.
Fishbein, M. (1975). i Ajzen, I.(1975). Belief, Attitude, Intention, and Behaviour: An Introduction to Theory and Research.
Anderson, J. C., & Gerbing, D. W. (1988). Structural equation modeling in practice: A review and recommended two-step approach. Psychological bulletin, 103(3), 411.
Ong, C. S., Lai, J. Y., & Wang, Y. S. (2004). Factors affecting engineers’ acceptance of asynchronous e-learning systems in high-tech companies. Information & management, 41(6), 795-804.
Cohen, P. A. (1981). Student ratings of instruction and student achievement: A meta-analysis of multisection validity studies. Review of Educational Research, 51(3), 281-309.
Chow, W. S., & Chan, L. S. (2008). Social network, social trust and shared goals in organizational knowledge sharing. Information & Management, 45(7), 458-465.
Guilford, J. P. (1965). Fundamental statistics in psychology and education. 4th ed., New York: McGraw-Hill.
Davenport, T. H., & Prusak, L. (1998). Working knowledge: How organizations manage what they know. Boston, MA: Harvard Business School Press.
Davis, F. D. (1989). Perceived usefulness, perceived ease of use, and user acceptance of information technology. MIS quarterly, 13(3), 319-340.
David, F.R. (2009). Strategic Management: Concepts and Cases. 12th ed. FT Prentice Hall
Fornell, C., & Larcker, D. F. (1981). Evaluating structural equation models with unobservable variables and measurement error. Journal of marketing research, 18(1), 39-50.
Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security (TISSEC), 5(4), 438-457.
Gottschalk, P. (1999). Strategic information systems planning: the IT strategy implementation matrix. European journal of information systems, 8(2), 107-118.
Grover, V. (1993). An Empirically Derived Model for the Adoption of Customer‐based Interorganizational Systems. Decision sciences, 24(3), 603-640.

Hair, J. F., Anderson, R. E., Tatham, R. L., & William, C. (1998). Black (1998), Multivariate data analysis.
Hausken, K. (2006). Returns to information security investment: The effect of alternative information security breach functions on optimal investment and sensitivity to vulnerability. Information Systems Frontiers, 8(5), 338-349.
Igbaria, M., Zinatelli, N., Cragg, P., & Cavaye, A. L. (1997). Personal computing acceptance factors in small firms: a structural equation model. MIS quarterly, 21(3), 279-305.
Karimi, J., Gupta, Y. P., & Somers, T. M. (1996). The congruence between a firm’s competitive strategy and information technology leader’s rank and role. Journal of Management Information Systems, 13(1), 63-88.
Kshetri, N., & Dholakia, N. (2002). Determinants of the global diffusion of B2B e-commerce. Electronic Markets, 12(2), 120-129.
Kuan, K. K., & Chau, P. Y. (2001). A perception-based model for EDI adoption in small businesses using a technology–organization–environment framework. Information & management, 38(8), 507-521.
Lesjak, D., & Vehovar, V. (2005). Factors affecting evaluation of e-business projects. Industrial Management & Data Systems, 105(4), 409-428.
Liang, H., Saraf, N., Hu, Q., & Xue, Y. (2007). Assimilation of enterprise systems: the effect of institutional pressures and the mediating role of top management. MIS quarterly, 31(1), 59-87.
Marin, L., & Ruiz, S. (2007). “I need you too!” Corporate identity attractiveness for consumers and the role of social responsibility. Journal of business ethics, 71(3), 245-260.
Melville, N., Kraemer, K., & Gurbaxani, V. (2004). Review: Information technology and organizational performance: An integrative model of IT business value. MIS quarterly, 28(2), 283-322.
Sobel, M. E. (1982). Asymptotic confidence intervals for indirect effects in structural equation models. Sociological methodology, 13(1982), 290-312.
Money, W., & Turner, A. (2005). Assessing knowledge management system user acceptance with the technology acceptance model. International Journal of Knowledge Management (IJKM), 1(1), 8-26.
Morton, M. S. S. (1991). The corporation of the 1990s: Information technology and organizational transformation. Oxford University Press on Demand.
Moulton, R., & Misra, S. (1991, October). A strategic framework for information security management. In Proceedings of the 14th Computer Security Conference.
Pirouz, D. M. (2006). An overview of partial least squares. Available at SSRN 1631359.
Podsakoff, P. M., & Organ, D. W. (1986). Self-reports in organizational research: Problems and prospects. Journal of management, 12(4), 531-544.
Poon, P., & Wagner, C. (2001). Critical success factors revisited: success and failure cases of information systems for senior executives. Decision support systems, 30(4), 393-418.
Preacher, K. J., Rucker, D. D., & Hayes, A. F. (2007). Addressing moderated mediation hypotheses: Theory, methods, and prescriptions. Multivariate behavioral research, 42(1), 185-227.
Premkumar, G., & King, W. R. (1994). Organizational characteristics and information systems planning: An empirical study. Information Systems Research, 5(2), 75-109.


Premkumar, G., & Ramamurthy, K. (1995). The Role of Interorganizational and Organizational Factors on the Decision Mode for Adoption of Interorganizational Systems. Decision sciences, 26(3), 303-336.
Rai, A., Lang, S. S., & Welker, R. B. (2002). Assessing the validity of IS success models: An empirical test and theoretical analysis. Information systems research, 13(1), 50-69.
Ravichandran, T., Lertwongsatien, C., & LERTWONGSATIEN, C. (2005). Effect of information systems resources and capabilities on firm performance: A resource-based perspective. Journal of management information systems, 21(4), 237-276.
Raymond, L. (1990). Organizational context and information systems success: a contingency approach. Journal of Management Information Systems, 6(4), 5-20.
Russell, D., & Gangemi, G. T. (1991). Computer security basics. " O'Reilly Media, Inc.".
Ryan, J. J., & Ryan, D. J. (2006). Expected benefits of information security investments. Computers & Security, 25(8), 579-588.
Schendel, D., & Hofer, C. W. (Eds.). (1979). Strategic management: A new view of business policy and planning. Little, Brown.
Schriesheim, C. A., Kinicki, A. J., & Schriesheim, J. F. (1979). The effect of leniency on leader behavior descriptions. Organizational Behavior and Human Performance, 23(1), 1-29.
Schultz, E. E., Proctor, R. W., Lien, M. C., & Salvendy, G. (2001). Usability and security an appraisal of usability issues in information security methods. Computers & Security, 20(7), 620-634.
Seddon, P. B. (1997). A respecification and extension of the DeLone and McLean model of IS success. Information systems research, 8(3), 240-253.
Straub, D., Limayem, M., & Karahanna-Evaristo, E. (1995). Measuring system usage: Implications for IS theory testing. Management science, 41(8), 1328-1342.
Sledgianowski, D. (2006). Decisions concerning IT infrastructure integration: a case study of a global chemical company. Journal of Information Technology Case and Application Research, 8(1), 55-71.
Smith, M. (1989). Computer security-threats, vulnerabilities and countermeasures. Information Age, 11(4), 205-210.
Szajna, B. (1996). Empirical evaluation of the revised technology acceptance model. Management science, 42(1), 85-92.
Teo, T. S., & King, W. R. (1997). Integration between business planning and information systems planning: an evolutionary-contingency perspective. Journal of management information systems, 14(1), 185-214.
Thong, J. Y., Yap, C. S., & Raman, K. S. (1996). Top management support, external expertise and information systems implementation in small businesses. Information systems research, 7(2), 248-267.
Tornatzky, L. G., & Fleischer, M. (1990). The Processing of Technological Innovation, The Journal of Technology Transfer, 16(1), 45-46.
Venkatesh, V. (2000). Determinants of perceived ease of use: Integrating control, intrinsic motivation, and emotion into the technology acceptance model. Information systems research, 11(4), 342-365.
Von Solms, R. (1996). Information security management: the second generation. Computers & Security, 15(4), 281-288.
Wade, M., & Hulland, J. (2004). Review: The resource-based view and information systems research: Review, extension, and suggestions for future research. MIS quarterly, 28(1), 107-142.
Weill, P., & Vitale, M. (2002). What IT infrastructure capabilities are needed to implement e-business models?. Mis Quarterly, 1(1), 17.
Wetzels, M., Odekerken-Schröder, G., & Van Oppen, C. (2009). Using PLS path modeling for assessing hierarchical construct models: Guidelines and empirical illustration. MIS quarterly, 33(1), 177-195.
連結至畢業學校之論文網頁點我開啟連結
註: 此連結為研究生畢業學校所提供,不一定有電子全文可供下載,若連結有誤,請點選上方之〝勘誤回報〞功能,我們會盡快修正,謝謝!
QRCODE
 
 
 
 
 
                                                                                                                                                                                                                                                                                                                                                                                                               
第一頁 上一頁 下一頁 最後一頁 top