研究生(外文):Yu-Jen Tsao
論文名稱(外文):The effect of Information Security Management System in Hospitals on the Maturity of Information Security
指導教授(外文):Hsin-Hui Lin
外文關鍵詞:ConflictInformation Security PolicyInformation Security MaturityInformation Security Management SystemCoordination MechanismInformation Security Management Acceptance
隨著資訊科技的發展和進步,資訊安全議題已成為醫療院所重視的最重要課題。就以醫院為例,不論是服務的中斷或組織資料外洩時,其對於民眾的生命健康或醫院形象,甚至於營運都可能會造成重大的影響。近年來,全球資訊安全事件不斷發生,為保護組織內部資訊相關資產並保持組織正常運作,導入資訊安全管理系統(Information Security Management System,簡稱ISMS)是一套可有效進行控制與管理之方法。國際間建構資訊安全管理系統通常採用ISO27001資訊安全管理規範為標準,以此標準來管理組織內部資訊的運用、資訊硬體的安全以及資訊使用者的控管,以達成資訊資產的「機密性」、「完整性」及「可用性」。
In recent years, with the advancement and development of information technology, the issue of information security has become the most important of hospitals. Taking the hospital for example, whether the service is interrupted or data is leaked, it will damage people’s lives or health, or the image of the hospital. In recent years, security incidents continue to occur, for the protection of information assets within maintain the computer operation, information security management system (ISMS) is a set of effective control and management methods. Commonly it used ISO standard call “ISO 27001”, for the organization to use of information, hardware, users and assets to achieve “confidentiality”、 “Integrity” and “availability” .
Most of previous studies of information security management focused on information security management and evaluation, but there were no methods for making information security maturity advanced and no analyses of factors that influenced on information security maturity. We had little information from previous studies if there would be conflict because of members of the organizations had different information security management acceptance, and then, this conflict would influence on executing and preserving the information security policy. Meanwhile, we also have little information if information security policy would influence on coordination mechanism and information security maturity, and the conflicts among organization members would influence on the coordination mechanism, and then influenced on information security maturity. We focused on information security and used technology acceptance model to deduce the acceptance of information security and we used the perspective of coordination mechanism to see how coordination influenced on information security maturity.
We used LISREL and SPSS to do path analysis, and found that both of information security management acceptance differences and conflicts among members would influence on the information security policy made by organization, meanwhile, they also influenced on the organization coordination systems. Information security maturity would be influenced by the organization coordination system and information security policy. Information security management acceptance did not show a significant correlation with conflicts among the members. But according to the results of interviews, we found that information security management acceptance also influenced on organization conflicts in user’s view. Furthermore, we provided some information security management related points in helping organization information security maturity advanced and also provided some references for further studies.
論文審定書 i
論文提要 ii
誌謝 iii
中文摘要 iv
英文摘要 vi
目錄 viii
圖目錄 xi
表目錄 xii
第一章 緒論 1
1.1研究背景與動機 1
1.2研究目的 2
1.3研究流程 3
第二章 文獻探討 4
2.1 資訊安全 4
2.2 ISO標準組織 5
2.3 資訊安全管理系統(ISMS) 5
2.3.1 ISO 27001資訊安全管理系統發展演進 6
2.3.2 ISO 27001主要架構 8
2.4資訊安全管理措施接受度 9
2.5衝突理論 10
2.6安全政策理論 12
2.7協調理論 14
2.8資訊安全成熟度 15
第三章 研究設計與方法 17
3.1 研究假說與架構 17
3.2 研究構面定義與衡量項目 18
3.2.1 資訊安全管理措施接受度構面 18
3.2.2 資訊安全措施衝突構面 19
3.2.3 資訊安全措施政策構面 20
3.2.4 政策衝突協調構面 21
3.2.5 資訊安全成熟度構面 22
3.3 問卷設計與資料蒐集方法 23
3.3.1 問卷設計 23
3.3.2 問卷回收 23
3.3.3 資訊安全成熟度評估模式 24
3.4 資料分析方法 25
3.5 訪談 26
3.5.1訪談流程 26
3.5.2訪談資料分析 26
第四章 實證分析與討論 27
4.1敘述性統計分析 27
4.1.1樣本結構分析 27
4.1.2各構面之敘述性統計 28
4.2資訊安全成熟度評估模式分析 32
4.3各構面之信度、效度分析 33
4.3.1信度分析 33
4.3.2效度分析 35
4.4 LISREL模式分析 38
4.4.1 LISREL模式整體配適度 38
4.4.2 LISREL模式分析結果 41
4.5研究假說影響效果分析與驗證結果 46
4.6訪談 47
4.6.1訪談對象 47
4.6.2訪談意見彙整 47
4.6.3 訪談結果分析 50
第五章 結論與建議 51
5.1研究結論 51
5.2研究貢獻與管理意涵 54
5.2.1 研究貢獻 54
5.2.2 管理意涵 56
5.3研究限制 56
5.4未來研究建議 57
參考文獻 58
研究問卷 65
