研究生(外文):Chao-Jung Teng
論文名稱(外文):The Phased Key Success Factors on the Military Body Obtains ISO 27001
指導教授(外文):Tuan-An Shu
中文關鍵詞:關鍵成功因素ISO 27001
外文關鍵詞:Key SucceedISO 27001
摘 要

近年來國防洩密情事頻傳,資訊安全事件不斷發生,分析事件單位面對安全威脅無法防禦的主要原因是防禦方式只有單點運作,缺乏全面的整體防線,部份有心人士運用日新月異的網路科技、進行各種滲透、破壞及竊密行為,已到了所謂無孔不入的地步,網路安全已儼然是網路世代的高科技攻防戰,國軍肩負國防安全的第一線,資通安全相對重要,如何有效建置資訊安全管理系統是目前軍事機構單位不容忽視,且必須面臨的課題。ISO 27001為目前國際公認最完整之資訊安全管理標準。本研究以通過ISO 27001認證之軍事機構個案單位為研究對象,以深度訪談為主、其他相關資訊安全文件及取得ISO 27001認證學術文獻資料為輔,探討軍事機構取得ISO 27001認證之階段性關鍵成功因素。
受限於能力及時間,本研究只針對該個案單位進行研究,希望此項研究結果能提供其他軍事機構做為取得ISO 27001認證參考依據,有效且順利的建置符合國際標準的資訊安全環境,事先防範資安事故的發生,確保國防資訊安全,國家機密才能真正滴水不漏,使敵人無可乘之機。

關鍵字:ISO 27001、關鍵成功因素

In recent years, the blabbing secret of national defense occurred frequently, the accident of information security found constantly. The principal cause why department, which made the fault, unable to prevent from those threat is that the protection was executed singly. Where locks a whole plan to protect.
Someone who use the fast changing technology, Internet, to penetrate department, to damage information, and to steal secret. Those actions has been all-pervasive doing. Security of internet has become a battle of high-tech of internet generation. Military is the front of national security. So that security of information and communication was more important. In military, it cannot be ignored or evaded that how to set up an effective system, which was use to manage information and communication. ISO 27001 is the most complete information security management standards that was recognized by internationally. In this research, department of military, which is adopted certification of ISO 27001, was object of study. This thesis takes depth interview as major; documents of information security and literatures of ISO 27001 certification as subordinate for studying the key factors which influence the military department to adopt certification from ISO 27001.
In this study, we found the key factors for adopting certification in five stages:
Planning, educating, and training
The key factors are <high-order executive support and not promise>, <enterprise safe policies, goals, activities make clear>, <special project leader>, and <last advisor suitable information safety >.
Pondering of system and producing of documents
The key factors are <high-order executive support and not promise>, <suitable information safety last advisor>, and <degree not information-based >.
Trying, inner checking, and faults amending
The key factors are <high-order executive support and not promise>, <the staff are safe to information, and can't understand it assess risk, risk management acceptance and it accept it degree>, <audit and correct constantly>, and <complement by staff proper information safety education and training >.
Verifying and certification awarding
The key factors are <high-order executive support and not promise>, <is it can cooperate with suggestion of consultant firm to need>, coach a advisor by suitable information safety, and <are audit and correct constantly >.
Verifying constantly
The key factors are <high-order executive support and not promise>, it is safe in <enterprise policy, goal, activity make clear>, and <last advisor suitable information safety >.
It is for the reasons of limited time and inadequate resource that the object of study was chosen only one. The results of this research are able to be referred for the military agencies who want to obtain the certification of ISO 27001. The results also help to setup a safe information of environment which satisfied international standard. The final aim of this research is to guard against the accident of security information, to assure the safety of national defense information, and to destroy the opportunity of enemy attack.

Keyword:ISO 27001, Key Succeed
