研究生(外文):Chih-pin Wang
論文名稱(外文):A Study of the Development of Information Security Awareness Scale Using AHP and Delphi Methods
指導教授(外文):Rei-yao Wu
外文關鍵詞:Information SecurityInformation Security AwarenessAnalytic Hierarchy Process (AHP)Delphi Method
本研究依據NIST SP 800-16 資訊安全訓練需求與NIST SP 800-50 資訊安全認知訓練課程,並結合層級分析法與德菲法發展出一個「資訊安全認知評量表」,訂出9大主題與各主題內共24項資訊安全認知權重,讓各組織(單位)可運用此評量表對組織進行資訊安全認知評量,並作為資訊安全教育訓練規劃之參考。
1. 該機關內部人員在9大評量項目中,「法律與規範」及「組織與資訊安全」兩大項表現出較高的認知程度,而在「取得/開發/安裝/執行控制」、「技術控制」及「敏感性」三大項認知程度則較低。
2. 透過受訪人員權重分數進行統計分析,發現該機關現行資訊安全教育訓練對於內部人員在「組織與資訊安全」項目的認知程度能有效提升;但在「法律與規範」、「風險管理」及「取得/開發/安裝/執行控制」等3項認知程度的提升效果有限。
3. 該機關內部人員於24項資訊安全認知概念項目認知程度表現上,在「法律與規範」、「對策與控制」、「預期意外」、「必須知道」、「安全訓練」、「負責資安職權之人員」、「備份」、「品質保證/品質控制」、「單一識別碼」等資訊安全認知概念項目中認知程度較低。
Nowadays, the man-made factor resulted from “personnel” is the most important factor in the accidents which related to the information security. In order to improve the cognitive ability for each user and to prevent from the events about the information security, the users need to have a nice training based on his/her learning for the information security awareness.
In this thesis, based on NIST SP 800-16 (Information Technology Security Training Requirements: A Role-and-performance-based Model) and NIST 800-50 (Building an Information Technology Security Awareness and Training Program), the AHP and Delphi Method are applied to design “Information Security Awareness Scale” for all types of the organizations. The Scale of Information Security Awareness can be provided as the references for the information security education and training plans.
For the practical implements in the government organization, we have the conclusions listed below. First, for the employees in the government organization, the two items, “Law and Regulations” and “The Organization and IT Security”, are with the higher weights among the nine criticized items in the Information Security Awareness Scale. However, the three items, “Acquisition/ Development/ Installation/ Implementation Controls”, “Technical Controls” and “Sensitivity”, are with the lower weights in the Information Security Awareness Scale. Second, the cognitive ability for “The Organization and IT Security” is improved for the implements of the information security training. However, there is no prominent improvement on the cognitive abilities for “Law and Regulations”, “Risk Management” and “Acquisition/ Development/ Installation/ Implementation Controls”. Finally, for the employees in the government organization, the items, “Law and Regulations”, “Countermeasures and Control”, “Expect the Unexpected”, “Need to Know”, “Security Training”, “DAA and other Officials”, “Backup”, “Quality Assurance/Quality Control”, “Unique Identifiers” are with the lower weights among the twenty-four conceptual items in the Information Security Awareness Scale.
